CVE-2020-12147: Silver-Peak Unity Orchestrator

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing.

Affected products

  • Silver-Peak Unity Orchestrator: before 8.9.11\+ (fixed in 8.9.11\+); from 8.10, before 8.10.11\+ (fixed in 8.10.11\+); from 9.0, before 9.0.1\+ (fixed in 9.0.1\+)

Published 2020-11-05. Last modified 2026-06-17.